The package is small, has no runtime dependencies, and includes tests and a README. Its single maintainer and lack of a security policy reduce confidence in future fixes, while the repository remains identifiable and unarchived.
38%
Total Score
25
100
75
88
Only four releases were published, all clustered in August 2017, with no releases in the last nine years. That long release gap is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing prolonged inactivity.
The package has one registry maintainer. A single-person project can be viable, but combined with the prolonged inactivity it provides little evidence of ongoing maintenance capacity.
The repository has one star and no forks, offering little supporting evidence of community review or shared maintenance. Popularity is only supporting evidence, so this does not determine the score alone.
Composer is used for the build, but no security-scanning tooling is present. This is a modest transparency and maintenance gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.